CVE-2018-18071: High severity mercedes-benz mercedes me vulnerability
An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and a server might be intercepted. The app can be used to operate the Remote Parking Pilot, unlock the vehicle, or obtain sensitive information such as latitude, longitude, and direction of travel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18071?
The severity of CVE-2018-18071 is high with a score of 7.5.
What is CVE-2018-18071?
CVE-2018-18071 is a vulnerability in the Daimler Mercedes-Benz Me app for iOS that allows interception of encrypted data exchange between the app and a server.
How does CVE-2018-18071 affect the Daimler Mercedes-Benz Me app?
CVE-2018-18071 affects the Daimler Mercedes-Benz Me app by potentially allowing unauthorized interception of encrypted data exchange.
What can an attacker do with CVE-2018-18071?
An attacker exploiting CVE-2018-18071 could potentially intercept sensitive information, control the Remote Parking Pilot feature, and unlock the vehicle.
Is there a fix available for CVE-2018-18071?
It is recommended to update to the latest version of the Daimler Mercedes-Benz Me app to mitigate CVE-2018-18071.